Trang này chưa có bản dịch.

Privacy Policy

Effective date: September 29, 2026.

Kohana ("Kohana," "we," "us," or "our") is operated by Jose Felipe Ballestas Bermudez as an individual. This Privacy Policy explains what information we collect when you use the Kohana app, kohana.live, and related services (together, the "Service"), why we collect it, who we share it with, and the choices and rights available to you.

Some sections of this policy contain bracketed placeholders where a fact is still being confirmed, or depends on a decision we haven't finalized yet. We'd rather tell you that plainly than guess.

Who We Are

Kohana is currently operated by Jose Felipe Ballestas Bermudez, an individual based in Florida, United States — not (yet) through a registered company. Contact: [email protected].

Kohana is available worldwide, including to users located in the European Economic Area, the United Kingdom, and Brazil. Kohana is currently operated by an individual rather than a registered company. As we formalize Kohana as a registered business, we'll review what additional requirements apply in the regions where we have users and update this policy accordingly.

Information We Collect

Account information

When you create a Kohana account, our signup form asks for an email address, a username, and a password (stored only as a one-way cryptographic hash — the plain password is used momentarily to create or verify that hash and is not retained or logged). You may optionally add a social media link to your creator profile.

Our signup form does not ask for your real name, birth date, gender, or physical address. However, you may voluntarily include personal information — including your real name — in places we don't control the content of, such as support emails, content reports, your profile, or the novels and comments you post. We handle any such information the same way we handle the rest of your account data, but we can't prevent you from including it, and you should avoid sharing more than you intend to make available.

Content you create or interact with

If you publish a visual novel, post a comment, like a novel, or follow a creator, we store that content and activity against your account so the Service can display it back to you and to others. Whether you follow a given creator is not shown to that creator or to other users through any feature of the app — we and our moderation/support staff can see it, but it isn't published anywhere. (This is separate from notifications: if you follow a creator and opt into "Following" notifications, you — the follower — receive a notification when they publish; the creator is not told who follows them.)

If you create a private share link for a novel, we store the link, its expiration time, and basic metadata about the shared novel.

Device and usage information

We run our own first-party analytics — we do not use Google Analytics, Firebase Analytics, Mixpanel, or similar third-party analytics SDKs for this purpose. When you use the app, we automatically collect your device model, operating system version, app version, language/region settings, and a randomly generated install identifier for your device, along with basic usage events (such as which screens you open) to help us understand how the Service is used and to fix problems.

Push notifications

If you enable notifications, we store a device push token (provided by Apple or Google) together with your account and device install identifier, so we can deliver notifications to your device. Which categories of notification you receive (for example, new chapters from creators you follow, or comments on your novels) is decided entirely on your device — we don't keep a server-side record of which notification types you've turned on or off.

Crash and error reporting

We use Sentry, a third-party error-monitoring service, to help us find and fix bugs. When a crash or error is captured, Sentry records: your account identifier (if you're logged in) and device install identifier; device/OS/app version information; a city-and-region-level approximate location derived from your IP address (Sentry does not retain the raw IP address itself on the stored event, per our configuration); and a short history of recent in-app events leading up to the crash ("breadcrumbs"), which can include the URLs of network requests made by the app immediately before the error, such as calls to our own servers or to RevenueCat. We have not modified Sentry's default data collection beyond disabling storage of your raw IP address; we have not audited every possible field these breadcrumbs could contain in every situation.

Subscriptions and payments

Kohana offers optional paid subscriptions ("Good Ending" and "True Ending," each available monthly or annually) through the Apple App Store or Google Play. All billing is handled directly by Apple or Google — we never see or store your payment card details. We use RevenueCat, a subscription management service, to keep track of your subscription status (active, expired, cancelled, etc.); RevenueCat identifies your subscription using your Kohana account ID.

Advertising

If you don't currently have an active subscription recorded on your device, the app may show ads served through Google AdMob. On iOS, we ask for your permission (via Apple's App Tracking Transparency prompt) before allowing ads to use your device's advertising identifier for personalization; if you decline, you may still see ads, just less tailored to you. In the European Economic Area, the United Kingdom, Switzerland, and any other region Google's consent tooling determines requires it, you'll be shown a consent form (via Google's User Messaging Platform) before ads are personalized, and you can change your choice at any time from the app's ad privacy settings. Even where you decline personalization, some data processing for basic ad delivery, fraud prevention, and frequency capping may still occur — this is a normal part of how ad-serving networks operate, not something we can turn off entirely while showing ads at all. We have not independently audited which specific data fields AdMob's SDK transmits or which downstream partners receive it; that information is governed by Google's own disclosures.

Our subscription status check happens periodically (at login and at intervals while you use the app), not on every single ad request in real time — so there can be a short window after a subscription lapses, or while your device is offline, where the app's local record hasn't yet caught up.

Server logs

Like most online services, our servers automatically log technical information about requests made to them, including your IP address, general location (country, derived from your network), and your device install identifier. These log files are automatically deleted after 90 days.

Content moderation records

If you report content, or if a moderator reviews, warns, or takes action on an account (including yours), we keep a record of that action, including the reason given, so we can maintain consistent enforcement and handle appeals. Our moderation team uses Discord, a third-party communication tool, to coordinate internally on enforcement actions; this is an internal tool for our own team, not visible to other users, and we try to minimize the personal information included in these internal messages.

How We Use Your Information

We use the information described above to: provide, operate, and maintain the Service; verify your account and keep it secure; process subscription purchases and manage entitlements; moderate content and enforce our Community Guidelines and Terms of Service; send you transactional emails (such as email verification and password resets) and, if enabled, push notifications; show advertising to non-subscribers and measure its effectiveness; diagnose and fix bugs and crashes; understand how the Service is used so we can improve it; and comply with legal obligations and respond to lawful requests.

Legal basis for processing (EEA / UK users)

Where GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (account creation and core app functionality), our legitimate interests (security, fraud prevention, analytics, and improving the Service, balanced against your rights), consent (advertising personalization, where a consent prompt is shown), and compliance with a legal obligation (responding to lawful requests). You can withdraw consent at any time where processing is based on consent, without affecting processing carried out before the withdrawal.

Who We Share Information With

We share information with the following categories of service providers, each of whom processes it to provide their specific service, under their own privacy policies and (where applicable) our instructions:

  • Apple / Google — app distribution, push notification delivery, and subscription billing.
  • RevenueCat — subscription status tracking.
  • Google AdMob — advertising, for non-subscribers.
  • Sentry — crash and error reporting.
  • Cloudflare — network security and content delivery for our website and backend services.
  • ProtonMail — delivery of transactional emails.
  • Discord — internal coordination among our own moderation team.

We may also disclose information if required by law, to protect the rights, property, or safety of Kohana, our users, or others, or in connection with a merger, acquisition, or sale of assets (in which case we'll notify you).

Do we "sell" or "share" personal information? We do not sell personal information for money. Showing advertising through AdMob does mean device/advertising-identifier information is disclosed to Google to enable interest-based advertising across apps and services, not just within Kohana — under the CCPA/CPRA, we treat this as "sharing" personal information, even though no money changes hands for it. If you're a California resident, you can opt out of this sharing by emailing [email protected]. We currently handle these requests manually rather than through an automated in-app toggle or by detecting the Global Privacy Control signal, since neither is built into the app yet. (Kohana, as a solo-operator app, may not meet the CCPA's business-size thresholds that make this law legally mandatory for us in the first place — but we extend these rights to California users regardless.)

International data transfers

Kohana's own servers are located in the United States. If you use the Service from the EEA, UK, Brazil, or elsewhere, your information will be transferred to and processed in the United States, and by the third-party providers listed above, who may process data in other countries. Data in transit between your device and our servers is encrypted using HTTPS/TLS. As we formalize Kohana as a registered business, we'll review what additional data-transfer safeguards may apply and update this policy accordingly.

Age Requirement

Kohana requires account holders to be at least 13 years old. If you are in the EEA or UK, the age at which you can consent to this kind of processing on your own behalf may be higher than 13 under your country's law (GDPR allows member states to set this between 13 and 16) — if you are under the age your country requires, you should only use Kohana with a parent or guardian's consent. We do not currently verify age or country of residence beyond a self-reported confirmation at signup, and we don't operate a separate parental-consent flow. Kohana is not directed at children: our content, app-store listing, and marketing are aimed at a general, teen-and-up audience, not children under 13, and we don't design features to specifically attract children. On that basis, we do not consider Kohana a "child-directed service" under COPPA.

Content published on Kohana is subject to our Community Guidelines regardless of a user's age — we don't have a separate "mature" tier that unlocks restricted content, and our guidelines already prohibit sexual content, graphic violence, and other categories of harmful material.

If we learn that a child under 13 has provided us with personal information, we will delete it. If you're a parent or guardian and believe your child has provided us with personal information, please contact us.

Data Retention

We retain your account information for as long as your account is active. Some information may persist after you delete your account — see "Deleting Your Account" below. Server logs are retained for 90 days (see "Server logs" above), and account-deletion feedback you voluntarily submit is retained for 1 year (see "Deleting Your Account" below). If you don't sign in for 3 years, we treat your account as abandoned: we'll email you a warning 1 month beforehand, and if you haven't signed back in by then, your personal information is automatically deleted the same way as if you'd requested it yourself, with your published content kept and anonymized the same way too (see "Deleting Your Account"). [PLACEHOLDER — specific retention periods for analytics events, crash reports, moderation records, and backups are still being defined; subscription and transaction-related records will be retained at least as long as required for financial recordkeeping and tax purposes.]

Deleting Your Account

You can delete your account at any time from Settings in the app. Deletion happens in two stages, designed to give you a real chance to change your mind before anything is permanent:

  1. Immediately: your account is deactivated, all of your active sessions are logged out, and any novels you've published are hidden from other users (but not deleted).
  2. After 30 days: if you haven't logged back in, your personal information — email address, username, and password — is permanently deleted and cannot be recovered. Any novels you've published, along with their comments and likes, stay up, but are no longer connected to your identity in any way: your username is replaced with a generic "Deleted User" label everywhere it would otherwise appear.

We keep published content up by default (rather than deleting it) for the same reason most platforms with comment sections or shared content do: a comment or a published novel isn't only "yours" once other people have read it, replied to it, or liked it — deleting it out from under them the moment you leave would erase their experience of the Service too, not just yours. What we can and do fully delete, without exception, is everything that identifies you personally.

If you'd rather have your published novels, comments, and likes deleted too — not just anonymized — email us at [email protected] and let us know; we'll erase them completely on request rather than only stripping your identity from them.

If you log back in at any point during the 30 days, the deletion is automatically cancelled and everything — your account and your hidden novels — is restored exactly as it was, with no separate "undo" step to take.

When you request deletion, we send you an email explaining this, with an optional link to a short form asking why you're leaving. If you fill it out, we store only your email address and what you wrote — deliberately not linked back to your account — for up to 1 year, so that your feedback isn't lost even after your account itself is gone.

Moderation records (such as past warnings) and subscription/transaction history are not deleted when your account is, for the reasons described in "Data Retention" above. Information already sent to third-party services (such as crash reports on Sentry, or our moderation team's internal Discord messages) is retained according to those services' own practices; we don't currently have an automated way to delete specific historical records from them on request, though we will do so manually on request where feasible.

If your account has been banned, you can still request deletion by emailing [email protected], since a ban prevents you from logging in to use the in-app deletion flow.

Your Rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, object to or restrict certain processing, and lodge a complaint with your local data protection authority (for EEA/UK users) or the ANPD (for Brazilian users, under the LGPD). To exercise any of these rights, contact us at [email protected]. We will ask for enough information to reasonably verify it's really you (or your authorized representative) making the request, and will respond within the timeframe required by applicable law — generally within 30 days for GDPR/UK GDPR requests and 15 days for LGPD requests, extendable where the law allows and we tell you why.

California residents

If you're a California resident, the categories of personal information described above may be considered "personal information" under the CCPA/CPRA. You have the rights described in "Your Rights" above, plus the right to non-discrimination for exercising them. See "Do we sell or share personal information?" above regarding advertising-related sharing.

Brazil (LGPD)

If you're in Brazil, the rights in "Your Rights" above apply to you under the Lei Geral de Proteção de Dados, including the right to confirmation of processing, correction, anonymization or deletion of unnecessary data, data portability, and information about who we share your data with. You may also lodge a complaint with the ANPD.

Security

We take reasonable measures to protect your information, including hashing passwords and using encrypted connections, but no method of storage or transmission is completely secure, and we can't guarantee absolute security.

Changes to This Policy

We may update this Privacy Policy from time to time. We'll update the effective date at the top of this page when we do, and, for material changes, try to notify you through the app or by email in advance where required by law.

Contact Us

Questions about this Privacy Policy, or a rights request? Email us at [email protected].